Skip to content
| Marketplace
Sign in
Visual Studio Code>Other>Claude Safe Auto AcceptNew to Visual Studio Code? Get it now.
Claude Safe Auto Accept

Claude Safe Auto Accept

manu yehezkely

|
33 installs
| (1) | Free Trial
Auto-approve routine Claude Code permissions while keeping risky actions under your control. Built-in safety net for dangerous commands. 200 free approvals, then $9.99 for 7,000 more.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Claude Safe Auto Accept

Stop clicking Allow. Keep Claude Code moving — safely.

Claude Safe Auto Accept automatically approves routine Claude Code tool permission prompts so Claude can keep working without constant interruptions — except for questions Claude asks you (AskUserQuestion) and plan reviews (ExitPlanMode), which always still prompt normally. A built-in safety net also keeps a short list of risky commands (force-push, hard reset, recursive deletes, credential-file edits) prompting even in auto-accept mode.

Unlike unrestricted permission bypassing, this extension is designed to preserve those safety protections rather than blindly approving everything.

Why "Safe" Auto Accept?

The goal is to remove repetitive approval prompts without removing the protections that actually matter. Today that means:

  • ✅ Routine tool permissions are automatically approved.
  • ✅ Dangerous shell commands remain protected (git push --force, git reset --hard, git branch -D, rm -rf, PowerShell recursive/force delete).
  • ✅ Destructive Git operations remain protected (covered by the same risky-pattern list above).
  • ✅ Credential-sensitive file edits remain protected (.env, *.pem, id_rsa, credentials.json, secrets.json, etc.).
  • ✅ User questions (AskUserQuestion) still require your input.
  • ✅ Plan reviews (ExitPlanMode) still require your involvement.

All of the above is enforced by the risky-pattern list and hard-coded ask-tools described under How it works and Settings below — nothing here is aspirational marketing, it's what the shipped hook actually does. That list is configurable and, being regex-based, isn't foolproof — see Known limitations. Adds safety guardrails; does not guarantee that every automatically approved operation is safe.

⚠️ Read this before enabling

Claude Safe Auto Accept removes most of Claude Code's confirmation prompts, including for running shell commands and editing or deleting files. Per Anthropic's own documentation, bypassing permission prompts provides "no protection against prompt injection or unintended actions." Only enable this in projects and environments you trust, and keep the built-in risky- pattern safety net turned on unless you have a specific reason to disable it.

Free quota & paid top-ups

The first 200 lifetime auto-approved tool calls are free. Questions, plan reviews, and anything caught by the risky-pattern safety net are unlimited and never count against the quota — only genuine auto-accepts do.

Once the quota (free + purchased) runs out, Claude Safe Auto Accept does not stop working or start denying anything — it simply falls back to Claude Code's normal interactive prompting for every tool call, exactly as if it were disabled, until you add more.

$9.99 buys 7,000 more approvals via Lemon Squeezy:

  • Claude Safe Auto Accept: Buy More Approvals opens the checkout page.
  • After purchase you'll get a license key by email — redeem it with Claude Safe Auto Accept: Redeem License Key.
  • The status bar shows remaining quota (142/200 free, or total remaining once you've purchased credits), and switches to a warning style once you're out.

Local counters, backed by a lightweight server-side check. Both the free-quota counter and the purchased-credit balance live in local files (~/.claude-auto-accept/stats.json, license.json) — that stays the day-to-day source of truth, and hook.ts (the script Claude Code actually invokes) never touches the network, before or after this. Periodically — and right after redeeming a license key — the extension reports your current counts, keyed by VS Code's own machineId (vscode.env.machineId, a random per-install id VS Code itself generates, not a hardware identifier), to a small optional Cloudflare Worker + D1 backend, which remembers the highest value it's ever seen for that id. If your local files are ever missing or show a lower count than the server remembers, the extension repairs them back up instead of starting fresh. This raises the bar against resetting your usage by deleting local files — it's not a guarantee. It doesn't defend against reinstalling VS Code (which gets a fresh machineId) or against modifying the extension's own code, which ships as ordinary, readable JavaScript like any VS Code extension. Only machineId and the two numeric counters are ever sent — never file contents or command text. See CLOUDFLARE.md for the full picture, including exactly what's sent and how it's hosted.

How it works

Claude Code (both the CLI and its official VS Code extension) supports a PreToolUse hook: an external script registered in .claude/settings.json that Claude Code runs before every tool call, and that returns an allow / ask / deny decision. This extension:

  1. Ships a small, dependency-free Node.js hook script.
  2. When you enable it, registers that script as a PreToolUse hook in your global ~/.claude/settings.json — applies to all your projects, alongside any hooks you already have (nothing else is touched).
  3. The hook auto-allows every tool call, except:
    • AskUserQuestion and ExitPlanMode always fall through to the normal interactive prompt.
    • Anything matching a risky pattern (see below) falls through to ask.
  4. Every decision is logged to ~/.claude-auto-accept/decisions.log and streamed live into the "Claude Safe Auto Accept" Output Channel.

There is no way for a VS Code extension to click buttons inside another extension's UI — this hook mechanism is the only supported integration point, which is why enabling/disabling writes real Claude Code configuration rather than trying to watch the screen.

Usage

  • Click the "Safe Auto Accept" status bar item (bottom right) to toggle it on/off. It also shows a running count of how many tool calls have been auto-accepted (hover for the full allow/ask/deny breakdown). Or use the Command Palette:
    • Claude Safe Auto Accept: Enable
    • Claude Safe Auto Accept: Disable
    • Claude Safe Auto Accept: Toggle
    • Claude Safe Auto Accept: Show Log
    • Claude Safe Auto Accept: Buy More Approvals
    • Claude Safe Auto Accept: Redeem License Key

Settings

Setting Description
claudeAutoAccept.riskyPatterns Array of rules; each matches a tool + field (e.g. Bash command, or Edit/Write file_path) against a regex and forces ask or deny instead of auto-allow. Ships with defaults for git push --force, git reset --hard, git branch -D, recursive/force deletes, and credential-shaped file paths (.env, *.pem, id_rsa, etc.).
claudeAutoAccept.additionalAskTools Extra tool names that should always fall through to interactive prompting, beyond AskUserQuestion and ExitPlanMode (which are always ask, regardless of this setting).

Changes to these settings are written to ~/.claude-auto-accept/config.json and picked up on the hook's next invocation.

Known limitations

  • Command matching is regex/substring-based, not a real shell parser — it can be evaded by sufficiently obfuscated commands. Defaults are written to favor false positives (an extra prompt) over false negatives.
  • v1 only manages the global ~/.claude/settings.json scope (applies to every project), not per-project .claude/settings.json.
  • Requires node to be available on your PATH (the hook script runs as a plain Node process spawned by Claude Code).
  • Free-quota and purchased-credit tracking gets a server-side backstop keyed by VS Code's machineId (see Free quota & paid top-ups and CLOUDFLARE.md), but that id changes on a fresh VS Code install/profile, and the check can be bypassed by modifying the extension's own code. It raises the bar against casual resets; it isn't a hard guarantee.

License

MIT — see LICENSE.

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft